06-09-2010 12:48 PM - edited 02-21-2020 04:41 PM
Please Advise.
C7206
(C7200P-ADVENTERPRISEK9-M), Version 12.4(24)T1
, RELEASE SOFTWARE (fc3)
Problem – IPSEC causing very high CP Utilization:
Global Statistics
-----------------
5 sec CPU util 93%/92% Timestamp 3w3d
Queue Statistics
----------------
Exec Count Total CPU Response Time Queue Length
(avg/max) (avg/max)
Critical 1 4 0/0 1/1
High 0 0 0/0 0/0
Normal 1416 8 0/4 1/7
Low 25 272 0/0 1/2
Common Process Information
-------------------------------
PID Name Prio Style
-------------------------------
5 Check heaps L New
Interface w/crypto map:
5 minute input rate 252433000 bits/sec, 317754 packets/sec
5 minute output rate 244181000 bits/sec, 305097 packets/sec
VPN Acceleration Module Version II+ in slot : 2
Statistics for Hardware VPN Module since the last clear
of counters 2141074 seconds ago
4751593 packets in 4751593 packets out
3386057046 bytes in 3360571566 bytes out
2 paks/sec in 2 paks/sec out
12 Kbits/sec in 12 Kbits/sec out
0 pkts compressed 0 pkts not compressed
0 bytes before compress 0 bytes after compress
1.0:1 compression ratio 1.0:1 overall
207945 commands out 207945 commands acknowledged
Last 5 minutes:
6713 packets in 6713 packets out
22 paks/sec in 22 paks/sec out
136129 bits/sec in 135149 bits/sec out
Errors:
ppq full errors : 0 ppq rx errors : 0
cmdq full errors : 0 cmdq rx errors : 0
ppq down errors : 0 cmdq down errors : 0
no buffer : 0 replay errors : 0
dest overflow : 0 authentication errors : 0
Other error : 0 Raw Input Underrun : 0
IPSEC Unsupported Option: 0 IPV4 Header Length : 0
ESP Pad Length : 0 IPSEC Decompression : 0
AH ESP seq mismatch : 0 AH Header Length : 0
AH ICV Incorrect : 0 IPCOMP CPI Mismatch : 0
IPSEC ESP Modulo : 0 Unexpected IPV6 Extensio: 0
Unexpected Protocol : 0 Dest Buf overflow : 0
IPSEC Pkt is fragment : 0 IPSEC Pkt src count : 0
Invalid IP Version : 0 Unwrappable : 0
SSL Output overrun : 0 SSL Decompress failure : 0
SSL BAD Decomp History : 0 SSL Version Mismatch : 0
SSL Input overrun : 0 SSL Conn Modulo : 0
SSL Input Underrun : 0 SSL Connection closed : 0
SSL Unrecognised content: 0 SSL record header length: 0
PPTP Duplicate packet : 0 PPTP Exceed max missed p: 0
RNG self test fail : 0 DF Bit set : 0
Hash Miscompare : 0 Unwrappable object : 0
Missing attribute : 0 Invalid attrribute value: 0
Bad Attribute : 0 Verification Fail : 0
Decrypt Failure : 0 Invalid Packet : 0
Invalid Key : 0 Input Overrun : 0
Input Underrun : 0 Output buffer overrun : 0
Bad handle value : 0 Invalid parameter : 0
Bad function code : 0 Out of handles : 0
SSL Output overrun : 0 SSL Decompress failure : 0
SSL BAD Decomp History : 0 SSL Version Mismatch : 0
SSL Input overrun : 0 SSL Conn Modulo : 0
SSL Input Underrun : 0 SSL Connection closed : 0
SSL Unrecognised content: 0 SSL record header length: 0
PPTP Duplicate packet : 0 PPTP Exceed max missed p: 0
RNG self test fail : 0 DF Bit set : 0
Hash Miscompare : 0 Unwrappable object : 0
Missing attribute : 0 Invalid attrribute value: 0
Bad Attribute : 0 Verification Fail : 0
Decrypt Failure : 0 Invalid Packet : 0
Invalid Key : 0 Input Overrun : 0
Input Underrun : 0 Output buffer overrun : 0
Bad handle value : 0 Invalid parameter : 0
Bad function code : 0 Out of handles : 0
Access denied : 0 Out of memory : 0
NR overflow : 0 pkts dropped : 0
Warnings:
sessions_expired : 0 packets_fragmented : 0
general : 0 compress_bypassed : 0
HSP details:
hsp_operations : 207965 hsp_sessions : 25
06-19-2010 06:21 AM
Please post "sh proc cpu" output couple of times when usage is high. I don't see any errors on the vam module.
Check the following link too
http://www.cisco.com/en/US/products/hw/routers/ps133/products_tech_note09186a00800a70f2.shtml
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide